Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47701

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 7.7

Описание

A flaw was found in OpenTelemetry Operator for Kubernetes. A tenant with permissions to create or update a ServiceMonitor resource can configure the bearerTokenFile field to point to the Collector's service account token path. This causes the Collector to send its mounted service account JSON Web Token (JWT) to an attacker-controlled scrape target. This vulnerability allows for information disclosure, potentially granting the attacker the same level of access as the OpenTelemetry Collector pod's service account within the Kubernetes API. This could lead to further enumeration and identification of targets, and potentially reading other sensitive files on the Collector pod.

Отчет

A flaw was found in the OpenTelemetry Operator for Kubernetes. The TargetAllocator preserves the ServiceMonitor bearerTokenFile field through to the Collector's Prometheus scrape configuration. A tenant who can create or update a ServiceMonitor can set bearerTokenFile to the Collector's mounted service account token path, causing the Collector to send its JWT to an attacker-controlled scrape target on every scrape interval. Red Hat OpenShift distributed tracing 3.10 ships a fixed version of the operator (>= 0.152.0) and is not affected.

Меры по смягчению последствий

Upgrade to opentelemetry-operator 0.152.0 or later, which adds DenyFSAccessThroughSMs support to drop ServiceMonitor and PodMonitor endpoints that reference arbitrary files on the file system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift distributed tracing 3opentelemetry-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2499680opentelemetry-operator: OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
github
около 2 месяцев назад

OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

7.7 High

CVSS3